Introduction
This Privacy Policy explains how Kunming PengHong Trading Co., Ltd., operating as PengHong, collects, uses, stores, and protects personal information when you visit this website or use our services. The site was developed by PengHong, our founding engineer, and is maintained to the highest standards of data stewardship.
We understand that privacy is fundamental to trust. This document is written to give you a complete and transparent picture of what happens to your data, why we process it, and the control you hold over it. Please read this policy carefully. If you do not agree with any part of it, you should stop using the website and our services and contact us with your concerns.
By accessing the website at https://www.penghong.lat or engaging our engineering services, you acknowledge that you have read and understood the practices described here. We update this policy from time to time, and the latest version will always be available on this page.
Who We Are
PengHong is the trading name of Kunming PengHong Trading Co., Ltd., a company focused on computer systems design and related services within the professional, scientific, and technical services sector. We provide cloud architecture, data platforms, network and infrastructure engineering, software integration, and cybersecurity services to businesses across a range of industries.
For the purposes of applicable data protection law, Kunming PengHong Trading Co., Ltd. acts as the data controller for the personal information described in this policy. This means we decide why and how your information is processed when you interact with our website, submit an inquiry, or use our services.
Our registered address is Room 1109, 11/F, Golden Sun Office Building, 11 Longquan Road, Wuhua District, Kunming - 650000, China (CN). You can reach us at any time using the contact details in the Contact Us section at the end of this policy.
Information We Collect
We collect several categories of information, and we limit our collection to what is necessary to operate the website and deliver our services effectively. The categories are described below.
Information you provide directly
- Contact details, such as your name, email address, and telephone number when you complete a contact or inquiry form.
- Business information, such as your company name, role, and project details that you include in a message.
- Communications, including the content of emails, support requests, and feedback you send to us.
Information collected automatically
- Technical data, including your internet protocol address, browser type, operating system, device type, and screen resolution.
- Usage data, including pages visited, time spent on pages, referring URLs, and interactions with site elements.
- Approximate location data derived from your internet protocol address at a city or region level only.
We do not collect sensitive personal information such as health data, biometric data, or government identifiers unless you voluntarily provide such information as part of a specific service engagement.
We also collect information in aggregated and de-identified form for statistical purposes. Where information has been fully de-identified so that it can no longer be linked to you, it is no longer treated as personal information under this policy and may be used for analysis, product improvement, and research.
How We Collect Information
We collect information through three principal channels. First, information you give us directly when you fill out a form, send an email, call our office, or otherwise communicate with our team. Second, information collected automatically through cookies, log files, and similar technologies when you browse the website. Third, information provided by third parties, such as analytics providers that report aggregate usage statistics back to us.
We do not use deceptive collection methods, and we do not obtain personal information by scraping public sources for marketing purposes. Where a service we use collects information on our behalf, that provider is bound by contract to process the data only under our documented instructions and for the purposes we define.
How We Use Your Information
We use the information we collect for clearly defined purposes connected to running our business and serving you. These purposes include the following.
- To respond to inquiries and provide the information you request about our services.
- To prepare proposals, estimates, and scopes of work for prospective and existing clients.
- To deliver, operate, and improve our computer systems design and engineering services.
- To communicate with you about project status, service updates, and support matters.
- To maintain the security and integrity of our website, systems, and networks.
- To analyze usage patterns and improve the design, content, and performance of the website.
- To meet our legal, regulatory, and contractual obligations, including record keeping and compliance.
We do not use your personal information to make automated decisions that produce legal or similarly significant effects without human review and your awareness. We also do not engage in the sale of personal information, and we do not share personal information for cross-context behavioral advertising. Any future change to this position would be clearly disclosed in an updated version of this policy.
Marketing Communications
We may send you informational and promotional communications about our services, industry updates, and company news, but only where you have requested or consented to receive such communications, or where we have a legitimate interest in contacting business contacts about relevant services.
Every marketing email we send includes a clear unsubscribe mechanism, and you may opt out at any time by following that link or by contacting us directly. Opting out of marketing communications does not affect transactional messages we need to send you in connection with an active service engagement, such as invoices, project updates, and security notices.
We honor your communication preferences across all channels. If you tell us you do not wish to receive promotional contact, we will record that preference and respect it across email, telephone, and any other channel we use to communicate with you.
Legal Bases for Processing
Where data protection law requires a legal basis for processing personal information, we rely on one or more of the following grounds.
- Consent, where you have given clear permission for a specific purpose and can withdraw that permission at any time.
- Contractual necessity, where processing is required to perform a contract with you or to take steps at your request before entering a contract.
- Legitimate interests, where processing is reasonably necessary for operating our business, provided your rights and interests do not override those needs.
- Legal obligation, where we must process information to comply with applicable law, regulation, or a valid legal request.
When we rely on legitimate interests, we carefully balance our interests against your privacy rights and document that assessment. You have the right to object to processing based on legitimate interests as described in the Your Rights and Choices section.
International Data Transfers
Our primary operations are based in China, and the information we collect is generally stored and processed there. In some cases, service providers located in other countries may process information on our behalf. When we transfer personal information across borders, we take steps to ensure it receives a level of protection consistent with this policy and applicable law.
These steps include using contractual clauses approved by the relevant authorities, selecting providers with recognized security certifications, and limiting transfers to the minimum data necessary. By using our website and services, you understand that your information may be transferred to, and processed in, countries whose data protection laws may differ from those in your own.
Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. The specific retention period depends on the type of information and the reason we hold it.
- Inquiry and correspondence records are typically retained for up to twenty four months after the matter is closed, to allow follow up and continuity of service.
- Contractual and financial records are retained for the period required by applicable accounting and tax law.
- Analytics data is stored in aggregate or anonymized form wherever possible and is periodically reviewed for deletion.
When information is no longer needed, we securely delete or anonymize it. If deletion is not immediately possible for technical reasons, we isolate the data from further use until it can be permanently removed.
Data Security
We implement technical and organizational measures designed to protect personal information against accidental loss, unauthorized access, alteration, disclosure, or destruction. Our measures include encryption of data in transit and at rest, access controls based on the principle of least privilege, network monitoring, and regular security reviews.
Our engineering team applies the same security discipline to our own systems that we apply for clients. Access to personal information is limited to personnel who require it to perform their duties, and all personnel are bound by confidentiality obligations.
No method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will investigate promptly and notify you and any relevant authorities where required by law.
We also maintain a documented incident response plan and conduct regular staff training on data protection and security practices. Our internal systems are subject to periodic penetration testing and vulnerability assessments so that weaknesses are identified and remediated before they can be exploited.
Your Rights and Choices
Depending on your location and the law that applies to you, you may have rights regarding your personal information, including the rights listed below.
- The right to access, meaning you can request a copy of the personal information we hold about you.
- The right to rectification, meaning you can ask us to correct inaccurate or incomplete information.
- The right to erasure, meaning you can ask us to delete your personal information in certain circumstances.
- The right to restrict processing, meaning you can ask us to limit how we use your information.
- The right to data portability, meaning you can request your information in a structured, commonly used format.
- The right to object, meaning you can object to processing based on legitimate interests or for direct marketing.
- The right to withdraw consent, where processing is based on consent, at any time without affecting prior processing.
To exercise any of these rights, contact us using the details in the Contact Us section. We will respond within the timeframes required by law and may ask you to verify your identity before fulfilling a request. We do not charge a fee for handling a valid request unless it is manifestly unfounded or excessive.
If you believe we have not handled your request or your personal information correctly, you have the right to lodge a complaint with the data protection supervisory authority in your jurisdiction. We encourage you to contact us first so that we can attempt to resolve the matter directly and quickly.
Privacy for Children
Our website and services are intended for businesses and adult professionals. We do not knowingly collect personal information from children under the age of sixteen. If you are a parent or guardian and believe a child has provided us with personal information, please contact us and we will take steps to delete that information promptly.
If we learn that we have collected personal information from a child without verified parental consent, we will delete it as quickly as possible. We encourage parents and guardians to supervise their children during online activity and to instruct them never to provide personal information through websites without permission.
Third-Party Links and Services
Our website may contain links to third-party websites, plugins, or services that are not operated by us. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit.
When you interact with a third-party service through our site, that service may collect information about you independently. We recommend reviewing the privacy settings and policies of those services before providing any personal information to them.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the effective date at the top of this page and, where appropriate, provide a more prominent notice on the website.
We encourage you to review this policy periodically so you remain informed about how we protect your information. Your continued use of the website after any changes to this policy take effect constitutes your acceptance of the revised policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the details below. We take privacy matters seriously and will respond to your inquiry as promptly as possible.
- Company: Kunming PengHong Trading Co., Ltd.
- Address: Room 1109, 11/F, Golden Sun Office Building, 11 Longquan Road, Wuhua District, Kunming - 650000, China (CN)
- Email: reply@penghong.lat
- Phone: +12344462389
- Website: https://www.penghong.lat